Viewing profile — anderslemke
anderslemke
HN member- Joined
- Mon, Feb 04, 2019, 9:08 AM UTC
- HN karma
- 44
- Public activity
- 18 items
- HN profile
- View on Hacker News ↗
About anderslemke
No profile information was provided.
Recent public activity
-
comment
Comment #25252076
I get where you're coming from, and this is something I've been thinking a lot about. It would be possible to not save the map, and then use some kind of hashing to infer user ids …
-
comment
Comment #25114529
Yes. Promise keeps a map of your sites and IDs.
-
comment
Comment #25109781
Promise is basically challenging the assumption that authentication has anything to do with both personal identity and being able to contact a user. If a site needs to contact the …
-
comment
Comment #25104230
I'm really happy that you're willing to take this discussion with me. I totally understand what makes IndieAuth is a good solution. And it seems really easy. For me. But I have no …
-
comment
Comment #25099695
Being a non-profit, collectively owned service, which Promise is, will make it difficult to ban users and relying parties. Just like the DNS can block users, Promise can ban users …
-
comment
Comment #25099186
That is an interesting point. Internet identity could maybe be a layered thing where one layer takes care of authentication, which is where Promise lives. The next layer could hand…
-
comment
Comment #25096457
That sounds painful in so many ways...
-
comment
Comment #25096401
Yes. The fragmentation is part of what makes authentication a horrible experience. But most of all, what I'm missing is at least one good option on the sign-in screen. And using a …
-
comment
Comment #25096290
I didn't know SimpleLogin. It seems really nice. Kind of what Apple does with their "Sign In with Apple". It's not exactly a SSO, though.
-
comment
Comment #25096166
Being pseudonymous is one of the main selling points of Promise. Only by being pseudonymous can it provide the level of privacy that should be expected from the global authenticati…
-
comment
Comment #25096111
I would love to understand the reasoning here. Sincerely. What makes OIDC a "non starter"? I see OIDC as an implementation detail, and have no strong opinions about it.
-
comment
Comment #25096072
Ok, you're not the first to say that... I hate it, when I type my email and password (correct, that is), and get an error saying "You already have an account. You need to sign in".…
-
comment
Comment #25096024
WebAuthn is great! I don't see any reason why Promise shouldn't implement it. I see it this way, that Promise makes it possible for all its relying parties leverage WebAuthn by imp…
-
comment
Comment #25095965
I'm a bit divided on whether or not the "centralized" thing is actually a problem Promise should tackle. On one hand, I want to tell you that Promise is only centralized by default…
-
comment
Comment #25093010
I've built Promise, to prove (to myself at least), that it would be technically possible to build authentication infrastructure, that can be used across sites, without having to st…
-
comment
Comment #25092808
The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authenticatio…
-
comment
Comment #23956575
Hi benzgou. It seems login.land is down. What happened?
-
comment
Comment #23956419
login.land seems to be down. What happened?